IP Library Granted Patent US 12,170,616
Granted Patent B2
US 12,170,616 · App. 18/103,366 · Granted Dec 17, 2024

Tunnel-based service insertion in public cloud environments

Inventors: Rahul Jain (Sunnyvale, CA); Kantesh Mundaragi (Bangalore, IN); Pierluigi Rolando (Santa Clara, CA); Jayant Jain (Cupertino, CA); Mukesh Hira (Palo Alto, CA)
Assignee: VMware LLC
H04L45/745G06F9/45558H04L12/4633H04L12/4641H04L49/354H04L49/70H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,170,616
App. No.
18/103,366
Granted
Dec 17, 2024
Kind
B2
Abstract

Example methods and systems are provided a network device to perform tunnel-based service insertion in a public cloud environment. An example method may comprise establishing a tunnel between the network device and a service path. The method may also comprise: in response to receiving a first encapsulated packet, identifying the service path specified by a service insertion rule; generating and sending a second encapsulated packet over the tunnel to cause the service path to process an inner packet according to one or more services. The method may further comprise: in response to receiving, from the service path via the tunnel, a third encapsulated packet that includes the inner packet processed by the service path, sending the inner packet processed by the service path, or a fourth encapsulated packet, towards a destination address of the inner packet.

Claims (39)

1. A method for performing a set of two or more services on packets, the method comprising:

at a cloud gateway (CGW) operating in a first network of a public cloud,

receiving, from a second network, a packet that is addressed to reach an external server in a third network;

performing a service insertion operation to identify a service path comprising two or more service machines for performing the set of two or more services on the packet;

based on the identified service path, forwarding the packet to the set of two or more service machines to perform the set of two or more services on the packet;

receiving the packet after the set of two or more services have been performed on the packet; and

forwarding the packet to the external server operating in the third network.

2. The method of claim 1 , wherein receiving the packet from the second network comprises receiving the packet from a machine operating in the second network.

3. The method of claim 2 , wherein the machine operates in a first virtual private cloud (VPC) that is defined in the same public cloud as the CGW, and the second network is the network that is defined for the first VPC, while the first network is a network that is defined in a second VPC in which the CGW operates.

4. The method of claim 3 , wherein the second VPC is defined to connect the second network to the third network.

5. The method of claim 3 , wherein the set of service machines operates in the first VPC.

6. The method of claim 3 , wherein the set of service machines operates in the second VPC.

7. The method of claim 3 , wherein the set of service machines is deployed in a third VPC, and a fourth network is the network that is defined for the third VPC.

8. The method of claim 1 , wherein the set of service machines is deployed in a private cloud.

9. The method of claim 1 , wherein the second network is a logical network.

10. The method of claim 1 , wherein the packet comprises a payload and a first header, the method further comprising:

at each service machine in the set of service machines,

receiving the packet comprising the payload and a second header addressing the service machine;

removing the second header from the packet;

performing the at least one service operation on the payload to obtain a processed payload; and

attaching a third header to the processed payload.

11. The method of claim 10 , wherein:

the second header addressing a first service machine in the set of service machines was attached by the CGW, and

forwarding the packet comprises removing a last header attached by a last service machine in the set of service machines and forwarding the processed payload to the external server through an uplink logical interface.

12. The method of claim 11 , wherein the CGW attaches a fourth header to the processed payload before forwarding the packet to the external server.

13. The method of claim 10 , wherein the third header specifies a destination address of the CGW, the method further comprising forwarding, from the CGW, the packet to another service machine to perform another service operation in the service path.

14. The method of claim 1 , wherein the CGW is a first CGW, and the first CGW and a second CGW are configured as a high availability (HA) pair.

15. The method of claim 1 , wherein the service path is a first service path, and the first service path and a second service path are configured as a high availability (HA) pair.

16. The method of claim 1 , wherein receiving from the second network, performing the service insertion operation, forwarding the packet to the set of service machines, receiving the packet after the set of services have been performed, and forwarding the packet to the external server are performed on an uplink logical interface of the GCW.

17. A non-transitory machine readable medium storing a program for execution by at least one processing unit for performing a set of two or more services on packets, the program comprising sets of instructions for:

at a cloud gateway (CGW) operating in a first network of a public cloud,

receiving, from a second network, a packet that is addressed to reach an external server in a third network;

performing a service insertion operation to identify a service path comprising two or more service machines for performing the set of two or more services on the packet;

based on the identified service path, forwarding the packet to the set of two or more service machines to perform the set of two or more services on the packet;

receiving the packet after the set of two or more services have been performed on the packet; and

forwarding the packet to the external server operating in the third network.

18. The non-transitory machine readable medium of claim 17 , wherein the set of instructions for receiving the packet from the second network comprises a set of instructions for receiving the packet from a machine operating in the second network.

19. The non-transitory machine readable medium of claim 18 , wherein the machine operates in a first virtual private cloud (VPC) that is defined in the same public cloud as the CGW, and the second network is the network that is defined for the first VPC, while the first network is a network that is defined in a second VPC in which the CGW operates.

20. The non-transitory machine readable medium of claim 19 , wherein the second VPC is defined to connect the second network to the third network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2024
From: JAIN, RAHUL; MUNDARAGI, KANTESH; ROLANDO, PIERLUIGI; JAIN, JAYANT; HIRA, MUKESH
To: VMWARE, INC.
Reel/Frame 069181/0972 →
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
Continuity (3)
Continuation 17133555 · Dec 23, 2020
Continuation 16251080 · Jan 18, 2019
Related Publication 20230171193A1 · Jun 1, 2023